Posted on 03/20/2004 5:09:50 PM PST by Salo
'Witty' Worm Wrecks Computers The worm targets Windows computers that run specific security firewalls.
By Brian Krebs washingtonpost.com Staff Writer Saturday, March 20, 2004; 7:02 PM
A quickly spreading Internet worm destroyed or damaged tens of thousands of personal computers worldwide Saturday morning by exploiting a security flaw in a firewall program designed to protect PCs from online threats, computer experts said.
(Excerpt) Read more at washingtonpost.com ...
Internet Security systems Security Alert
March 20, 2004BlackICE Witty Worm Propagation Synopsis: ISS X-Force has learned of a worm that is spreading via the ICQ parsing vulnerability in ISS products that was announced on March 18th. The worm targets unpatched versions of the BlackICE PC Protection product. If a vulnerable system is infected, the Witty worm attempts to propagate by scanning random IP addresses. The Witty worm progressively writes junk data to physical hard drives after transmitting 20,000 packets, causing data damage. Impact: The Witty worm uses hard-coded addresses and only has the ability to infect certain builds of the Protocol Analysis Module (PAM). The Witty worm is destructive to the target system, and overwrites key hard disk sectors after sending out its payload. The junk data written to disk may impact system stability and cause a "blue screen" to occur upon reboot. The Witty worm only infects specific builds of PAM listed below, and can only infect Win32 systems. Affected Versions: BlackICE Agent for Server 3.6 ebz, ecd, ece, ecf BlackICE PC Protection 3.6 cbz, ccd, ccf BlackICE Server Protection 3.6 cbz, ccd, ccf RealSecure® Network 7.0, XPU 22.4 and 22.10 RealSecure Server Sensor 7.0 XPU 22.4 and 22.10 RealSecure Desktop 7.0 ebf, ebj, ebk, ebl RealSecure Desktop 3.6 ebz, ecd, ece, ecf RealSecure Guard 3.6 ebz, ecd, ece, ecf RealSecure Sentry 3.6 ebz, ecd, ece, ecf Note: No Proventia products are affected by the Witty worm. The newest updates for all products are not vulnerable to exploitation. Description: The Witty worm exploits a stack-based overflow in ICQ response parsing in the Protocol Analysis Module (PAM) of ISS products. It is a memory- resident worm only, and contains no file payload. Witty propagates via UDP, sending UDP packets with a random destination and destination port. The source port of Witty traffic is 4000, and the source address is not spoofed. The worm will attempt to propagate immediately by sending copies of itself out across the wire to random targets. After sending a predefined number of packets, Witty attempts to open a randomly determined physical drive and write 64k of data to a random location. This cycle repeats for every 20,000 packets sent. Recommendations: ISS Product updates that address this vulnerability have been available since March 9, 2004. These updates are accessible via the ISS Download Center: http://www.iss.net/download/ ISS X-Force recommends that networks block UDP packets with a source port of 4000 at the network gateway to block inbound worm propagation. Data on infected systems may be damaged. ISS X-Force recommends that systems that are infected are removed from the network, and powered down. ISS X-Force further recommends that data recovery techniques are employed to assess damage and to recover data.
Doesn't sound quite as destructive as the Wash Pest would have us believe. However anyone who wants to throw up their hands over this one is quite welcome to mail me their "destroyed" computer or hard drive.
Frankly, I switched from Black Ice to ZoneAlarm a couple of years ago
And if Ferraris had been as numerous as Pintos, it would have been the Ferraris blowing up in rear-end collsions.
Go ahead... you'll feel better.
uh-kay!
ehhem.
Shoulda got a ... something that won't run black ice!
Oy... what else is there to say?
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.